CVE-2026-3930
vulnerability analysis and mitigation

Overview

CVE-2026-3930 is an unsafe navigation vulnerability in the Navigation component of Google Chrome on iOS that allows a remote attacker to bypass navigation restrictions via a crafted HTML page. It was reported by Povcfe of Tencent Security Xuanwu Lab on January 19, 2026, and patched on March 10, 2026, as part of the Chrome 146 stable channel release. The vulnerability affects Google Chrome on iOS prior to version 146.0.7680.71, and Microsoft Edge (Chromium-based) is also listed as an affected product. It carries a CVSS v3.1 base score of 5.3 (Medium) (Chrome Release, Feedly).

Technical details

The vulnerability is classified under CWE-288 (Authentication Bypass Using an Alternate Path or Channel), indicating that Chrome's iOS navigation subsystem fails to properly enforce navigation restrictions through an alternative code path. An attacker can exploit this by serving a specially crafted HTML page to a victim, which triggers the unsafe navigation behavior without requiring any privileges or user interaction beyond visiting the page. The bug was tracked internally as Chromium issue 476898368 and awarded a $1,000 bounty, reflecting its medium severity classification (Chrome Release).

Impact

Successful exploitation allows a remote attacker to bypass Chrome's navigation security restrictions on iOS devices, potentially redirecting users to unintended destinations or circumventing browser controls designed to protect users from malicious sites. The impact is limited to integrity (CVSS integrity impact: Low), with no direct confidentiality or availability consequences. This could be leveraged as part of a broader attack chain — for example, to redirect users to phishing pages or bypass same-origin navigation controls (Feedly).

Mitigation and workarounds

Google has addressed this vulnerability in Chrome 146.0.7680.71 for Linux and 146.0.7680.71/72 for Windows and Mac, released on March 10, 2026. Users running Google Chrome on iOS should update to version 146.0.7680.71 or later immediately. Microsoft Edge (Chromium-based) users should also apply the corresponding update from Microsoft. No configuration-based workarounds have been published; updating to the patched version is the only recommended remediation (Chrome Release, Microsoft MSRC).

Community reactions

The vulnerability was part of a broader Chrome 146 security update that addressed 29 security issues, including several Critical and High severity bugs, which received coverage from security news outlets such as GBHackers. The specific CVE-2026-3930 did not generate significant standalone commentary, consistent with its medium severity and lack of active exploitation. Downstream Linux distributions including Debian, Fedora, and openSUSE issued their own Chromium security advisories incorporating this fix (Chrome Release).

Additional resources


SourceThis report was generated using AI

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management